Lateral Movement Visualization for Network Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting and containing lateral network intrusions are overly manual and slow, making it difficult to quickly identify and remediate threats within the limited 'breakout time' before attackers can access critical data and resources.

Innovation Solution

An automated system for visualizing and remediating lateral movements in computer networks, which includes the collection and filtering of event logs, visual mapping of connections, and the ability to identify the initial infection vector and scale of intrusion, using a security computer machine with a processor and secure memory to render graphical images of network connections and provide contextual data for quick analysis and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If manual methods are used to detect and contain lateral network intrusions, then detection accuracy can be maintained, but the response time becomes too slow to effectively remediate threats within breakout time

Engineering Contradiction:
Improveresponse timeVSAvoidmanual operation level
Core Design Contradiction:
SpeedVSExtent of automation

Solution Approach 1:

The system performs preliminary actions by continuously collecting and analyzing network traffic data before intrusions fully establish themselves. Security rules are pre-configured to automatically detect lateral movement patterns, enabling the system to identify and respond to threats during the reconnaissance and credential gathering phases, rather than waiting for manual detection after full compromise.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical analysis with automated electronic systems. Machine learning models and automated correlation engines substitute for human analysts examining logs and network traffic. This substitution enables real-time processing of vast amounts of data at speeds impossible for manual methods, directly addressing the speed-response time contradiction.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive network monitoring is implemented to detect all lateral movement activities, then detection coverage is improved, but system complexity and resource consumption increase significantly

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies local quality by implementing detection rules tailored to specific network segments, host types, and threat scenarios. Rather than uniform monitoring across the entire network, security policies are customized for different zones and asset classes. This targeted approach maintains high detection coverage for critical areas while reducing overall system complexity and resource requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The monitoring system is segmented into modular components that can be independently deployed and configured. Detection rules are divided into discrete security policies that can be selectively enabled based on network needs. This segmentation allows the organization to implement comprehensive monitoring where required while maintaining simpler configurations elsewhere, balancing coverage with complexity management.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If detailed analysis of all network connections is performed to identify intrusion paths, then detection precision is improved, but the time required for analysis exceeds the limited breakout time available

Engineering Contradiction:
Improveintrusion detection precisionVSAvoidbreakout time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial action by focusing analysis on the most critical connection attributes and high-risk traffic patterns rather than examining every detail of all network communications. Automated correlation of key indicators enables precise intrusion path identification with sufficient speed to contain threats within breakout time, accepting that not every connection detail will be fully analyzed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system implements feedback loops where initial detection results immediately trigger automated response actions and refined analysis. As the system detects potential lateral movement, it dynamically adjusts monitoring focus to the affected network segments, concentrating analytical resources on the most relevant data. This feedback-driven approach achieves high precision without requiring exhaustive analysis of the entire network.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11425150B1Lateral movement visualization for intrusion detection and remediation
Publication Date: 2022.08.23 BANK OF AMERICA CORP
  • US11425150B1 patent drawing
  • US11425150B1 patent drawing
  • US11425150B1 patent drawing

AI summary

Aspects of the disclosure relate to visualization of lateral movements of an intruder on a network by connecting to computers and/or resources under investigation. A first computer is identified for investigation. Logs regarding incoming and outgoing connections to the computer are extracted and can be prefiltered based on specific IDs or other criteria. Maps of incoming and outgoing connections are stored in memory along with event information. Each subsequent computer to which the computer connected or resource accessed is identified. The map is updated based on logs from that computer or resource. A graphical image showing each applicable host, its connections, the chronology, and/or contextual information is generated and displayed. Individual hosts and other displayed data can be user-selectable to drill down and/or provide additional information. The process can repeat until all hosts, from patient zero to all endpoints, have been identified and rendered.